daily plain-text briefing: security, markets, business, and pittsburgh
Two easy-to-trigger, unauthenticated flaws land with working exploit code the same day—a WordPress core bug that runs code from one anonymous request and an OpenSSL denial-of-service that an 11-byte packet sets off.
Latest developments: The flaws now carry CVE identifiers including CVE-2026-60137, WordPress shipped the 7.0.2 release, and today the full exploit mechanism plus a working proof-of-concept went public.
wp2shell lets an anonymous HTTP request run code on a bare WordPress core install with zero plugins, putting every 6.9 and 7.0 site in range; Adam Kues of Assetnote and Searchlight Cyber traced it to a REST API batch-route confusion and SQL injection chain. Update to 6.9.5 or 7.0.2 at once.
Sources: Help Net Security · The Hacker News · ↑ top
Latest developments: Microsoft warned of a surge in ACR Stealer attacks against its enterprise customers, pulling browser-stored passwords, authentication tokens, and sensitive documents.
ACR Stealer, spread largely through ClickFix copy-paste lures, grabs credentials and session tokens that fuel follow-on intrusion. Reset exposed credentials and block the delivery lures.
Sources: BleepingComputer · ↑ top
Latest developments: Okta's Red Team disclosed HollowByte, showing an 11-byte TLS request forces an unpatched OpenSSL server to reserve up to 131 KB of memory for a message that never arrives, memory that stays gone on glibc systems until the process restarts.
Unauthenticated attackers can exhaust OpenSSL server memory and crash the service; OpenSSL quietly shipped the fix in June with no CVE, advisory, or changelog entry pointing at it. Move to the fixed OpenSSL build.
Sources: The Hacker News · BleepingComputer · ↑ top
Latest developments: Checkmarx uncovered seven malicious npm packages targeting the Vite frontend ecosystem, codenamed ViteVenom, expanding the ChainVeil campaign's four-tier blockchain command-and-control spanning Tron and other chains to deliver a remote access trojan.
The packages impersonate Vite tooling to drop a RAT on developers, using blockchain infrastructure that resists takedown. Audit dependencies and pull the malicious versions.
Sources: The Hacker News · ↑ top
Latest developments: A Go botnet named NadMesh surfaced in early July scanning for exposed ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio instances, and the operator's own dashboard claims 3,811 stolen AWS keys alongside Kubernetes tokens.
NadMesh runs a Shodan-fed scan queue to find self-hosted AI tools that teams stand up fast and firewall late, then harvests cloud credentials for further intrusion. Firewall and authenticate every AI service endpoint.
Sources: The Hacker News · ↑ top
Latest developments: Expel attributed the April 2026 DigiCert incident to CylindricalCanine, a subgroup of the Chinese group GoldenEyeDog, also tracked as APT-Q-27, Dragon Breath, and Miuuti Group, and laid out the code-signing certificate theft behind it.
GoldenEyeDog, known for hitting the gambling and gaming sectors, stole code-signing certificates through the DigiCert breach, letting it sign malware as trusted software. Watch for and block binaries signed with the abused certificates.
Sources: The Hacker News · ↑ top
Latest developments: Beyond Saturday's Saudi strike already reported, the Wall Street Journal reported Iran has switched to more-lethal missiles that made the past week the deadliest yet for commercial sailors in the Persian Gulf, while the U.S. Strategic Petroleum Reserve has drained to its lowest level since 1983.
The United States and Iran keep trading strikes on infrastructure and military targets across the Persian Gulf around the Strait of Hormuz, the chokepoint that once carried a fifth of the world's crude, raising the risk of a wider war and tightening global oil supply.
Sources: WSJ World News · WSJ World News · WSJ Markets · ↑ top
This Afternoon: Showers And Thunderstorms, high 87F.
Tonight: Showers And Thunderstorms then Chance Showers And Thunderstorms, low 66F.
Sunday: Mostly Sunny, high 82F.
Latest developments: Firefighters answered a call to South Aiken Avenue around 7:45 a.m. Saturday, July 18, and found flames at Fujiya Ramen.
A morning fire damaged the dining room and second floor of Fujiya Ramen on South Aiken Avenue in Pittsburgh, and Allegheny County 911 officials said no one was hurt; the cause is unknown, and whether the flames reached adjoining businesses is unclear.
Latest developments: Duquesne Light Company added crews Saturday, July 18, ahead of the forecast line of severe storms.
Duquesne Light Company increased staffing across its service territory as forecasters warned of widespread damaging winds and isolated tornadoes moving through the Pittsburgh region Saturday evening, conditions that threaten power outages.
Latest developments: Air-quality alerts across the Pittsburgh region ended before 10 a.m. Saturday, July 18, and forecasters posted a flash flood warning and watch as a line of thunderstorms carrying damaging winds, hail, and possible tornadoes drops south after 4 p.m.
A wind shift cleared the Canadian wildfire smoke that fouled the week's air across Western Pennsylvania, but strong to severe storms and flooding now threaten to delay games and events into Saturday evening.
Latest developments: A large water main break in the 3300 block of Churchview Avenue shut the congested road for hours in Baldwin Borough on Saturday, July 18.
The Baldwin Borough Police Department urged drivers to find alternate routes after the break disrupted water service and closed Churchview Avenue in the borough south of Pittsburgh.
Latest developments: The Post-Gazette laid out July 18 how consolidating the Duquesne City and McKeesport Area districts across the Monongahela River could help or hurt both cities and their students.
The Pennsylvania Department of Education is studying a merger that would give the long-troubled Duquesne City school district a partner in the McKeesport Area district, a step with financial and community stakes for both Mon Valley cities.
Sources: Pittsburgh Post-Gazette · ↑ top
Latest developments: The Pittsburgh Downtown Partnership moved Picklesburgh's Sunday opening earlier, to 11 a.m. through 7 p.m. on July 19, to help vendors recover after wildfire smoke thinned Friday and Saturday crowds.
Picklesburgh, the annual pickle-themed food festival in Downtown Pittsburgh, runs its final day Sunday, July 19; chief executive Jeremy Waldrup said the extended hours put the festival's small-business vendors first after an unprecedented weekend.
Pirates (50-47)
Fri Jul 17 · Pirates @ Guardians · Postponed
Up Next · Pirates @ Guardians · Sat Jul 18, 1:10 PM
Latest developments: The Post-Gazette's training-camp countdown July 18 cast free-agent signing Jamel Dean as the Steelers' bid to finally land an impact cornerback in free agency.
As the Steelers open camp at Saint Vincent College in Latrobe, the Post-Gazette framed newly signed cornerback Jamel Dean as the answer to a long drought at the position, working alongside Jalen Ramsey in Patrick Graham's secondary.
Sources: Post-Gazette Steelers · ↑ top
Latest developments: The Post-Gazette laid out five storylines to watch as the Pirates open the second half chasing a wild-card spot.
With ace Paul Skenes anchoring the rotation and a revamped offense, the Post-Gazette weighed the questions that will decide whether the Pirates stay in the National League playoff race.
Sources: Post-Gazette Pirates · ↑ top
Latest developments: Lindsey Heaps and her family told ESPN about her transfer to NWSL expansion side Denver Summit FC, a homecoming after globetrotting with the U.S. women's national team and Paris Saint-Germain.
U.S. women's national team midfielder Lindsey Heaps signed with Denver Summit FC, bringing her career back to Colorado after stops in France and beyond.
Sources: ESPN Soccer · ↑ top
S&P 500 7,524.56 ▼ -0.1% Dow 52,472.99 ▼ -0.4% Nasdaq 25,930.32 ▼ -0.5% WTI crude 79.70 ▲ +11.9% EUR/USD 1.1434 ▲ +0.1% GBP/USD 1.3444 ▲ +0.4% USD/JPY 162.28 = +0.0%